Privacy
No accounts, no tracking cookies, no cross-site tracking. What follows is what the code actually does — if the code changes, this page changes.
Controller
Carsten Sachse
Taunusstrasse 42a, 61440 Oberursel, Germany
Phone: +49 176 633 80 937 · Email: me@carstensachse.de
When you only look at the site
Our host writes standard server logs, including your IP address, browser and the page requested, and keeps them briefly for security and troubleshooting. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating the service securely.
We use Vercel Web Analytics to see how many people visit and which pages they view. It sets no cookies and stores nothing in your browser; visits are counted through a short-lived, anonymised hash that cannot identify you and expires within a day. These numbers are for operating the site and are not published. Legal basis: Art. 6(1)(f) GDPR; because nothing is stored on or read from your device, no consent banner is required (§ 25 TDDDG).
No advertising cookies, no cross-site tracking. The only thing stored in your browser is your light/dark preference, kept in localStorage under droptick-theme. It never leaves your device and is not used to recognise you. Legal basis for storing it: § 25(2) no. 2 TDDDG — it is what you asked for by pressing the toggle.
Logos on listing rows
Logos next to advertisers are currently fetched from Google's favicon service, which means your IP address reaches Google LLC when a page with listings loads. This is the same construction German courts have ruled on for embedded Google Fonts, and it is on the list to be replaced by icons served from our own domain. Until that is done, this paragraph is the disclosure, not a justification.
When you paste a URL
The address you enter is sent to our server, which requests that page once to read its title, description and icon so we can show you the listing before you buy anything. The site you entered will see a request from our server, not from you. We do not store the address unless you complete a purchase.
When you ask for the price
The price is shown once per 30 minutes per connection. To enforce that, our database keeps a marker keyed by your IP address for those 30 minutes, then deletes it. The same kind of short-lived marker (one per checkout window) stops the same connection from opening two checkouts at once. Legal basis: Art. 6(1)(f) GDPR — without it the hidden price could be read off by polling, which would defeat the service.
When you click the promoted link
The link goes through our server so the click can be counted; the count is public. We store a salted hash of your IP address and browser identifier for 24 hours, so the same visitor counts once a day, then it expires. The address itself is never stored and the hash cannot be walked back to you. Obvious crawlers are not counted. Legal basis: Art. 6(1)(f) GDPR.
When you buy a slot
Checkout runs on Stripe. Stripe collects your payment details, billing address, company name, email address and VAT ID. We never see card numbers. Stripe acts partly as our processor and partly as its own controller — see stripe.com/privacy.
We store, for the duration of the placement and our retention obligations:
- the week purchased, the category you picked, and the price paid,
- your company name, target URL, and its title, description and icon,
- the Stripe session reference.
Company name, target URL, price paid and the click count are shown publicly on this site — that is the product, and it is stated before you pay. Legal basis: Art. 6(1)(b) GDPR for performing the contract and Art. 6(1)(c) together with § 147 AO and § 257 HGB for the commercial records, which we keep for the statutory period.
What is public
Company name, destination link, category, week, price paid and click count are shown on the front page while your link runs and in the archive afterwards. Anyone can see them, including search engines, and past weeks stay visible as a record. They may also remain in backups for a limited time after a listing is taken down. Do not buy a slot if you do not want those details published — it is stated before you pay, and it is the product.
Processors and recipients
- Vercel Inc., USA — hosting, server logs and the cookieless visit statistics described above. Transfers are covered by the EU standard contractual clauses.
- Upstash — the database holding sales, click counts and the short-lived rate-limit markers described above.
- Stripe Payments Europe Ltd., Ireland, with Stripe Inc., USA — payments and invoicing.
- Google LLC, USA — favicon delivery, see above.
Data processing agreements are in place where required. We do not sell data and do not pass it to anyone beyond the recipients listed here.
Your rights
You have the right, free of charge and at any time, to information about the origin, recipients and purpose of the personal data we store about you, and to rectification, erasure, restriction of processing, data portability and objection under Art. 15–21 GDPR. Write to me@carstensachse.de.
You also have the right to complain to a supervisory authority (Art. 77 GDPR). The competent authority for us is the Hessischer Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden.
How long we keep things
These are the actual expiry times set in the code, not a general promise:
- Sale records (company, destination, price, week) — 2 years, then deleted automatically.
- The past-weeks list stops showing a sale after 1 year, even while it is still stored.
- Click counts — 2 year.
- Click de-duplication markers — 24 hours. Price-reveal markers — 30 minutes. Checkout reservations — minutes. Payment event records (for not processing the same webhook twice) — three days.
Invoices are a separate matter: they are issued and stored by Stripe and kept for the periods required by German tax and commercial law (§ 147 AO, § 257 HGB). Deleting our copy of a sale does not and cannot delete the invoice behind it.
Droptick · last updated 30 August 2026 · this page describes the state of the code and is updated when the code changes.